I will set up wazuh siem and xdr for advanced threat detection
Network and Cybersecurity Engineer
About this Gig
Your servers and cloud workloads generate thousands of security events every day without a properly configured SIEM, most of those threats go unseen until it's too late.
I will deploy and configure Wazuh a leading open-source XDR and SIEM platform tailored to your infrastructure so you get real-time visibility into threats, anomalies, and security gaps.
What you get with this gig:
Wazuh Manager, Indexer, and Dashboard deployed on your cloud or on-prem server
Endpoint agent installation (Linux / Windows)
Real-time log collection and event correlation
File Integrity Monitoring (FIM) to track system file changes
Vulnerability Detection module configured for monitored endpoints
Custom detection rules tuned to minimize false positives
Alert notifications set up for high-severity threats (brute force, privilege escalation, suspicious logins)
Active Response setup (e.g., automated IP blocking via host firewalls)
A clean, intuitive dashboard with basic handover documentation
Why work with me?
I am a cybersecurity researcher and network engineer specializing in threat detection and security architecture. As I am building up my reviews on Fiverr my pricing is set lower than market rates.
Cloud provider:
VMware Cloud
Expertise:
Installation
•
Backup
•
Development
•
Performance
Cloud computing resource:
Security Groups
My Portfolio
FAQ
Do I need to provide a server, or do you provide hosting?
You will need your own server or cloud VM (AWS, DigitalOcean, Azure, Linode, or on-premises). For an All-in-One deployment (Manager + Indexer + Dashboard), a minimum of 8GB RAM and 2 vCPUs running Ubuntu 20.04/22.04 LTS is required for smooth log indexing.
Is Wazuh really free?
Yes, Wazuh is 100% open-source software. You are paying for my engineering expertise to correctly install, configure, tune, and harden the system for your network.
Can you deploy Wazuh on public cloud providers (AWS/Azure/GCP)?
Yes! I can deploy it on any major cloud provider, VPS provider, or local virtualized environment (VMware, Proxmox, VirtualBox) as long as I have SSH or management access.
Will I be able to see live alerts and logs right after delivery?
Absolutely. You will receive login credentials to a fully working web dashboard displaying real-time events, endpoint statuses, and security alerts from your connected agents.
What is "Active Response" in the Premium tier?
Active Response allows Wazuh to automatically take action when a threat is detected — such as executing a host firewall rule to block an attacker's IP address after repeated failed SSH login attempts.
What if I need more than 6 agents or a multi-node cluster?
No problem at all! Send me a message detailing your requirements, and I will send you a custom offer tailored to your exact network scale.
